#vulnerability research
17 stories taggedvulnerability research.

Anthropic's AI Agents Went to War With Each Other When Given Conflicting Goals
New research from Anthropic shows that its Claude AI models, left to compete over the same task, independently developed and deployed self-replicating malware against each other. The findings raise pointed questions about what happens when AI systems are put to work at scale without clear rules for how they should interact.

AI Is Spitting Out Working Exploits for $3.61. Microsoft Says the Old Playbook Is Dead.
A senior Microsoft security chief told Black Hat USA that AI tools have made finding and weaponising software flaws so cheap and fast that the entire industry's approach to defence needs to change, starting now.

Plug-and-Play Trick Turns a Fake USB Stick Into Full Windows 11 Takeover
Researchers show how Windows' helpful habit of auto-installing driver software can be twisted into SYSTEM-level control, and it works over Remote Desktop too.

OpenAI hands a specialised hacking AI to a small club of security firms
GPT 5.6 Cyber is locked behind a partner programme called Daybreak, with the likes of IBM, Cisco and CrowdStrike getting first dibs.

The Security Scanners Protecting Your Code Could Be the Way Hackers Get In
A researcher found that five unnamed security vendors' own scanning tools could be tricked into handing over cloud passwords, production databases, and developer credentials, just by feeding them a rigged code repository.

Microsoft Debuts Its First Cybersecurity-Only AI Model Inside MDASH
The company says pairing MAI-Cyber-1-Flash with GPT-5.4 scored 95.95% on CyberGym at half the cost of its previous best setup.

Microsoft's New AI Security Service Can Find Bugs, Simulate Attacks and Write Patches, All in Minutes
Project Perception strings together a team of specialised AI agents to do what used to take a room full of security experts. But the real story is how Microsoft built it to work without the biggest, most expensive AI models.

Anthropic's Opus 5 Can Find Software Bugs Almost as Well as Its Most Powerful AI, But Can't Turn Them Into Weapons
The company's new mid-tier model gets close to its top system on spotting security flaws. Exploit-writing is another story.

AI Finds Bugs Fast. Proving They're Real Still Takes a Human.
AI tools can scan code and spit out vulnerabilities at speed, but a finding is worthless until someone shows it actually works. Here's why that gap matters for anyone worried about software security.

Intruder's AI 'vulnerability vending machine' finds a WordPress zero-day on its own
A security firm wired large language models into code-analysis tools and produced a working exploit for an unknown plugin flaw. It says more disclosures are on the way.

AI Is a Force Multiplier for Defenders and Attackers Both, Says Check Point CTO
Jonathan Zanger says every AI platform his team examined over the past year had serious security flaws. The fix is not to avoid AI. It is to build security in from the start.

ChocoPoC: The Fake Exploit Repos Turning Bug Hunters Into Victims
A Python-based infostealer is hiding inside GitHub proof-of-concept code marketed to vulnerability researchers, siphoning credentials, cookies, and files before dropping a remote shell.

Anthropic's AI Model Found Vulnerabilities in Classified U.S. Government Systems
An unnamed U.S. official says Anthropic's Mythos model identified security flaws in sensitive government infrastructure during a joint exercise with intelligence agencies.

OpenAI Hands GPT-5.5-Cyber to 'Trusted Defenders' Under Daybreak
The model is pitched at deep codebase analysis and vuln patching. The interesting part is who gets access — and what shows up in the post-mortem when they don't.

Mythos Isn't Vapor: Inside the SAST Tool Quiet-Skeptics Are Starting to Believe
A short defense of a controversial static analysis startup, and what its findings actually look like under the hood.